You probably noticed it. A meeting invite from a company you’ve never heard of. No context. No prior email. Just suddenly, there it is, sitting on your calendar like it belongs there.
That’s not a glitch. That’s a strategy.
The invite I got recently was from a company called ArgoMetrix. I never signed up for anything. I certainly didn’t request a meeting.
But there it was. Automatically added. With a reminder set.
Calendar spam works because it exploits the one filter email never had… we still psychologically treat scheduled time as legitimate.
This isn’t a bug in Google Calendar. It’s the exploitation of a fundamental assumption baked into the protocol, that if something is on your calendar, you probably put it there.
Why Email Spam Filters Created Calendar Spam
Here’s the system dynamic nobody talks about… spam filters got good. Really good. So the people who depend on unsolicited outreach to survive started looking for surface areas that weren’t defended yet.
Email was patched. Calendar wasn’t.
The ICS protocol1, the standard behind calendar invites, was designed in an era when you got invites from colleagues and meeting organizers, not from automated mass-prospecting tools. It trusts. By design.
So now you have a whole category of AI-assisted sales automation that doesn’t bother emailing you at all. It just... books time. The psychology is deliberate, when something is already on your calendar, you feel compelled to respond. Accept. Decline. Anything. And any response confirms your address is live and the owner pays attention.
That’s the whole game.
How They Got Your Email in the First Place
If you’re a developer, or really anyone who’s ever touched a public GitHub repo, spoken at a conference, or downloaded a whitepaper, your email is almost certainly in multiple sales databases right now, tagged with attributes you’d find uncomfortably accurate.
The pipeline is systematic:
GitHub commits are the most underappreciated leak vector. Every commit you’ve ever pushed to a public repo likely contains Author: Name <email@domain.com>. Scrapers have been harvesting these for years. That data gets enriched, sold, and fed into outreach platforms like Apollo, ZoomInfo, and RocketReach.
Domain enumeration handles the gaps. If you use a custom domain, bots try dave@, david@, dev@, admin@, and quietly validate which ones bounce. The survivors go into the list.
LinkedIn correlation ties it all together. Scraping tools match profiles to company domains to GitHub usernames to conference attendee lists, reconstructing your likely email even if you never published it directly.
You didn’t give them your email. They assembled it. From the digital exhaust you didn’t know you were leaving.
Developers are particularly targeted because sales databases tag us as “technical decision makers.” If you’re working on AI infrastructure, cloud tooling, or dev platforms, you’re a high-value lead for an entire ecosystem of B2B SaaS companies burning VC money to hit growth numbers.
The Fix Is Four Settings
The good news… this is entirely solvable. Google Calendar has the controls. Most people just never turned them on.
1. Stop auto-adding invitations. In Google Calendar Settings → Event Settings → “Automatically add invitations”, change it to “Only if I respond to the invitation in email.” Unknown senders can no longer insert events directly. Invites sit in your email until you decide.
2. Kill Gmail’s automatic event extraction. Also in Event Settings, turn off “Automatically add events from Gmail to my calendar.” This stops Google from helpfully extracting webinar promotions and marketing events out of your inbox and turning them into calendar items.
3. Add a Gmail filter for ICS files. In Gmail’s filter creation, use:
filename:ics OR "invited you to" OR "calendar invitation"
Set it to skip inbox or delete. Better version if you want to preserve internal invites:
filename:ics -from:@yourcompany.com
4. Report, don’t just delete. When a spam event does appear, open it, hit the three dots, and select Report as spam. You’re training Google’s filters, not just cleaning up your own view.
The Tracking Trick Security Engineers Use
One more technique worth knowing, especially if you want to trace which company leaked or sold your email.
Gmail supports plus-addressing. dave@gmail.com and dave+github@gmail.com are the same inbox. So if you sign up for services with tagged variants, dave+aws, dave+conference2024, dave+thatSaaSfreeTrial, and spam later appears at one of those addresses, you know exactly who sold the list.
It’s not foolproof. Some services strip the plus tag. But it catches more than you’d expect. Security researchers have used this to document vendors in direct violation of their own privacy policies.
You didn’t consent to be in their CRM. They scraped you, enriched you, and now they’re booking time on your calendar. The audacity isn’t accidental, it’s a feature of the business model.
The Bigger Pattern
What ArgoMetrix did is an edge case on a trend that is accelerating… AI-assisted outreach tools are eliminating friction between “find a prospect” and “occupy their attention.” Email required you to craft a message. A calendar invite requires almost nothing.
And as AI lowers the cost of generating personalized outreach at scale, the volume pressure on every undefended communication channel is going to increase. Calendar is just the current front. Voice, SMS, and social DMs are next in line.
The defense isn’t panic. It’s hygiene. Lock your defaults. Know your attack surface. Treat your calendar the same way you treat your inbox: assume anything from an unknown sender is hostile until proven otherwise.
Your time is the asset they’re after. Start protecting it like one.
Found this useful? Forward it to someone still wondering why a SaaS company they’ve never heard of just invited them to a “discovery call.”